CVE-2024-46626: SQL Injection
Published Oct 2, 2024
·Updated
OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.
Affected Software
2 affected components
OS4ED openSIS-Classic
OS4ED openSIS=9.1
Event History
Oct 1, 2024
Exploit Published
12:00 AM
Oct 2, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Apr 3, 2025
Known Exploited
01:45 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-46626?
CVE-2024-46626 is classified as a critical severity vulnerability due to its potential for exploitation through SQL injection.
2
How do I fix CVE-2024-46626?
To fix CVE-2024-46626, update OS4ED openSIS-Classic to the latest version where the vulnerability has been patched.
3
What type of vulnerability is CVE-2024-46626?
CVE-2024-46626 is a SQL injection vulnerability that allows an attacker to execute arbitrary SQL code on the database.
4
What are the potential impacts of CVE-2024-46626?
Exploitation of CVE-2024-46626 can lead to unauthorized data access, data leakage, or corruption of the openSIS database.
5
Who is affected by CVE-2024-46626?
CVE-2024-46626 specifically affects users of OS4ED openSIS-Classic version 9.1.